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DETAILED ACTION 
Claim Rejections - 35 USC § 102 
The following is a quotation of the appropriate paragraphs of 35 U.S.C. 102 that form the 
basis for the rejections under this section made in this Office action: 
A person shall be entitled to a patent unless - 

(b) the invention was patented or described in a printed publication in this or a foreign country or in public use or on 
sale in this country, more than one year prior to the date of application for patent in the United States. 

Claims 1-4, 6-12, and 14-18 are rejected under 35 U.S.C. 102(b) as being anticipated by 
Guthrie (200. 

As to claim 1, Guthrie shows: 

A method of improving accuracy in fraud screening for online transactions, the 
method comprising: 

providing a security cookie to a computer (Figure 1 , 60) of a customer who accesses a 

website (Figure 1, 30), where the security cookie includes a unique identifier (ID) 

that is assigned to the customer (Paragraph 0074); and 
if the customer accesses the website at a subsequent time, checking if the customer 

has exceeded a velocity value based upon the unique ID of the user (Paragraph 

0146). 

As to claim 2, Guthrie further shows: 

if the customer has exceeded the velocity value, then placing the order in an outsort 
queue for fraud analysis (Paragraph 0148). 
As to claim 3, Guthrie further shows: 
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if the customer has exceeded the velocity value, then evaluating, by an electronic 
commerce fraud detection module, the velocity value along with other indicators 
relating to the order to determine if the order is to be placed in an outsort queue 
for fraud analysis (Paragraph 0148). 
As to claim 4, Guthrie further shows: 

the velocity value comprises: a number of orders placed by the customer to the 
website within a particular defined time period (Paragraph 0146). 
As to claim 6, Guthrie further shows: 

the unique ID is integrated in a session cookie that provides security for transactions 
with the website (Paragraph 0074). 
As to claim 7, Guthrie further shows: 

a different unique ID is assigned to another user who accesses the website (Paragraph 
0025). 

As to claim 8, Guthrie shows 

A method of improving accuracy in fraud screening for online transactions, the 
method comprising: 

providing a security cookie to a computer (Figure 1 , 60) of a customer who accesses a 
website (Figure 1, 30), where the security cookie includes a unique identifier (ID) 
that is assigned to the computer (Paragraph 0074); and 

if the customer accesses the website at a subsequent time, checking if the customer 
has exceeded a velocity value based upon the unique ID (Paragraph 0176), 
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where the security cookie links multiple login names to a single customer to enable 
velocity analysis on an order placement from the customer, regardless of the login 
name that is used by the customer (Paragraph 0048). 
The Examiner interprets the use of multiple e-mail addresses described as being 
equivalent to login names. In the teachings of Guthrie, there can be multiple addresses 
associated with a single account and transactions can be directed to any of the addresses. 
As to claim 9, Guthrie shows: 

An apparatus for improving accuracy in fraud screening for online transactions, the 

apparatus comprising: 
a server (Figure 1 , 32) configured to provide a security cookie to a computer of a 
customer who accesses a website, where the security cookie includes a unique 
identifier (ID) that is assigned to the customer (Paragraph 0074); the server 
configured to check if the customer has exceeded a velocity value based upon the 
unique ID of the user, if the customer accesses the website at a subsequent time 
(Paragraph 0146). 
As to claim 10, Guthrie further shows: 

the server is configured to place the order in an outsort queue for fraud analysis, if the 
customer has exceeded the velocity value (Paragraph 0148). 
As to claim 11, Guthrie further shows: 

if the customer has exceeded the velocity value, then evaluating, by an electronic 
commerce fraud detection module, the velocity value along with other indicators 
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relating to the order to determine if the order is to be placed in an outsort queue 
for fraud analysis (Paragraph 0148). 
As to claim 12, Guthrie further shows: 

the velocity value comprises: a number of orders placed by the customer to the 
website within a particular defined time period (Paragraph 0146). 
As to claim 14, Guthrie further shows: 

the unique ID is integrated in a session cookie that provides security for transactions 
with the website (Paragraph 0074). 
As to claim 15, Guthrie further shows: 

a different unique ID is assigned to another user who accesses the website (Paragraph 
0025). 

As to claim 16, Guthrie shows: 

An apparatus for improving accuracy in fraud screening for online transactions, the 
apparatus comprising: 

a server (Figure 1 , 32) configured to provide a security cookie to a computer of a 
customer who accesses a website, where the security cookie includes a unique 
identifier (ID) that is assigned to the computer (Paragraph 0074); the server 
configured to check if the customer has exceeded a velocity value based upon the 
unique ID, if the customer accesses the website at a subsequent time (Paragraph 
0146), where the security cookie links multiple login names to a single customer 
to enable velocity analysis on an order placement from the customer, regardless of 
the login name that is used by the customer (Paragraph 0048). 
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The Examiner interprets the use of multiple e-mail addresses described as being 
equivalent to login names. In the teachings of Guthrie, there can be multiple addresses 
associated with a single account and transactions can be directed to any of the addresses. 
As to claim 17, Guthrie shows: 

An apparatus for improving accuracy in fraud screening for online transactions, the 

apparatus comprising: 
means for providing a security cookie to a computer of a customer who accesses a 
website (Figure 1, 32), where the security cookie includes a unique identifier (ID) 
that is assigned to the customer (Paragraph 0074); and 
means for checking if the customer has exceeded a velocity value based upon the 
unique ID of the user, if the customer accesses the website at a subsequent time 
(Paragraph 0146). 
As to claim 18, Guthrie shows: 

An article of manufacture, comprising: a machine-readable medium having stored 

thereon instructions (Paragraph 0035) to: 
provide a security cookie to a computer of a customer who accesses a website, where 
the security cookie includes a unique identifier (ID) that is assigned to the 
customer (Paragraph 0074); and 
check if the customer has exceeded a velocity value based upon the unique ID of the 
user, if the customer accesses the website at a subsequent time (Paragraph 0146). 
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Claim Rejections - 35 USC § 103 
The following is a quotation of 35 U.S.C. 103(a) which forms the basis for all 
obviousness rejections set forth in this Office action: 

(a) A patent may not be obtained though the invention is not identically disclosed or described as set forth in 
section 102 of this title, if the differences between the subject matter sought to be patented and the prior art are 
such that the subject matter as a whole would have been obvious at the time the invention was made to a person 
having ordinary skill in the art to which said subject matter pertains. Patentability shall not be negatived by the 
manner in which the invention was made. 

Claims 5 and 13 rejected under 35 U.S.C. 103(a) as being unpatentable over Guthrie in 
view of Kou (2002/0099936). 

Guthrie shows all of the elements of claims 1 and 9 from which claims 5 and 13 depend, 
but does not expressly show: 

the security cookie is separate from a session cookie that provides security for 
transactions with the website. 
Kou shows the use of a non-secure session cookie as well as a secure authcode cookie 
(Abstract). It would have been obvious to one of ordinary skill in the art at the time of the 
invention to have modified the teachings of Guthrie to include the usage of multiple cookies as 
shown by Kou for reasons including preventing unauthorized users from accessing sensitive web 
client or web site information (Kou, Abstract). 

Conclusion 

Any inquiry concerning this communication or earlier communications from the 
examiner should be directed to Joshua Murdough whose telephone number is (571) 270-3270. 
The examiner can normally be reached on Monday - Thursday, 7:00 a.m. - 5:00 p.m. 



Application/Control Number: 1 0/678,682 Page 8 

Art Unit: 4132 

If attempts to reach the examiner by telephone are unsuccessful, the examiner's 
supervisor, Khoi Tran can be reached on (571) 272-6919, The fax phone number for the 
organization where this application or proceeding is assigned is 571-273-8300. 

Information regarding the status of an application may be obtained from the Patent 
Application Information Retrieval (PAIR) system. Status information for published applications 
may be obtained from either Private PAIR or Public PAIR. Status information for unpublished 
applications is available through Private PAIR only. For more information about the PAIR 
system, see http://pair-direct.uspto.gov. Should you have questions on access to the Private PAIR 
system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would 
like assistance from a USPTO Customer Service Representative or access to the automated 
information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. 



Joshua Murdough 



KHOI H. TRAN 
SUPERVISORY PATENT EXAMINER 




